Chrome–Windows zero-day chain used by China-linked hackers shows NGOs’ exposure to espionage
Two China-linked threat groups exploited the same previously unknown Chrome–Windows flaws, using them to deploy a GRIMWEDGE backdoor against NGOs and to install LONGTALE, a credential-stealing Chrome extension.
A single exploit path through everyday software has given China-linked hackers a powerful way into some of the world’s most widely used systems.
Technical reporting describes how two China-linked threat actors used the same Chrome–Windows exploit chain against targets running Google’s browser on Microsoft’s operating system. One actor, tracked as UTA0560, used it to deploy a backdoor dubbed GRIMWEDGE against non-governmental organizations. Another, known as APT31, used the chain to install LONGTALE, a malicious Chrome extension designed to steal credentials.
The operations relied on a zero-day exploit chain: a sequence of vulnerabilities that software vendors have not yet discovered or patched. Exploiting that chain allowed attackers to break out of Chrome’s protections and gain higher privileges in Windows, turning a visit to a compromised web page or a malicious link into a route to system control.
For NGOs and civil-society groups, which often lack the security resources of governments or large firms, this presents a sharp risk. A backdoor like GRIMWEDGE planted via a browser exploit can expose internal communications, planning documents and contact networks. A credential stealer like LONGTALE can quietly harvest logins for email, cloud services and other tools that underpin daily operations.
The fact that both UTA0560 and APT31 drew on the same exploit chain points to shared tooling or fast reuse across multiple China-linked operations. Once a working chain exists for mainstream software such as Chrome and Windows, it can be applied to a wide range of targets without their needing to install any obvious malware themselves.
The broader lesson is that browsers and operating systems most people treat as basic utilities have become front doors for state-linked cyber activity. When attackers hold a viable zero-day chain, routine web use can give them access to sensitive accounts and data.
Key signals now are how quickly Google and Microsoft ship patches, how fast users apply them, and whether other groups start using the same exploit path. Any public attributions or sanctions tied to UTA0560 or APT31 would underline that governments see these operations as part of a strategic contest, not just ordinary cybercrime.
Sources
- OSINT